200-201 exam dumps

200-201 practice question 64 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 64

Select 3

A financial organization has implemented a time-based access control policy to restrict access to its internal resources. A security analyst has noticed that an employee is attempting to access critical systems outside of their designated working hours. Which of the following actions should the organization prioritize to ensure the effectiveness of the time-based access control policy?

  1. A

    Review and update the time-based access control policy to match employee schedules.

  2. B

    Enable logging to monitor access attempts outside of the designated time windows.

  3. C

    Disable time-based access control temporarily for troubleshooting purposes.

  4. D

    Configure alerts to notify security teams of access attempts outside permitted hours.

  5. E

    Grant exceptions to employees who need access outside of normal hours without additional review.

Show answer and explanation

Correct answers: A, B, D

Explanation

Time-based access control is designed to restrict access to resources during specific time windows, reducing the risk of unauthorized access. To ensure its effectiveness, organizations should regularly review and update the policy, monitor access attempts through logging, and configure alerts for timely incident response. Disabling controls or granting unrestricted exceptions can compromise security and should be avoided.

  • A. Correct.

    Reviewing and updating the policy ensures that the access control rules align with the actual work schedules of employees, minimizing false positives and policy violations.

  • B. Correct.

    Enabling logging helps track unauthorized access attempts and provides insights into potential security violations or misconfigurations.

  • C. Incorrect.

    Disabling time-based access control would leave the system vulnerable to unauthorized access and is not a recommended action.

  • D. Correct.

    Configuring alerts ensures that the security team is promptly informed of potential violations, allowing them to respond quickly.

  • E. Incorrect.

    Granting exceptions without proper review undermines the purpose of the time-based access control policy and could lead to security risks.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam